Transcript: ColdCard Is Compromised: What You Need to Do Now
Full speaker-labelled transcript of TFTC episode #777 with James O'Beirne.

Full speaker-labelled transcript of TFTC episode #777 with James O'Beirne. Read the written article: ColdCard Is Compromised: What You Need to Do Now. Click any timestamp to watch that moment on YouTube. Machine transcription, lightly cleaned, may contain errors.
James O'Beirne [0:07] You've had a dynamic where money's become freer than free. I mean, talk about a Fed just gone nuts. All, all the central banks going nuts. So it's all acting like safe haven. I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins. In the world of fiat currencies, Bitcoin is the victor. I mean, that's part of the bull case for Bitcoin.
Marty Bent [0:31] If you're not paying attention, you probably should be. Probably should be. Probably should be. Yeah, I don't think we can assume everybody's heard. And I know, I think that's a bad assumption just because I've been texting people I know have cold cards and they're completely oblivious to what was going on last night. So yeah, sad day.
James O'Beirne [0:53] Yeah, we've talked under better circumstances for sure.
Marty Bent [0:59] For those who are unaware, there is a massive vulnerability in Coldcards produced after 2021, all models, some worse than others, but essentially the random number generator that creates the entropy for private keys that you produce using the Coldcard is insufficient. Is that the right word? Yes.
James O'Beirne [1:26] Yeah, you could call it deterministic. So the search space required to get the private key, to guess the private key basically, is highly, highly limited relative to what it should be. So basically the funds under the MK2, MK3s with firmware between 2021 and 2023 are just kind of like dangling in the wind. So luckily, if you used dice rolls, if you used, say, over 99 dice rolls to initialize the key, you're safe. Or if you're using a passphrase, which is basically like the 25th word you can specify when you're setting up the wallet, if that passphrase is of a sufficient length and complexity, which is longer than most people think, then— you may also be safe. But yeah, the MK2, MK3s are affected severely to the point where it's like you need to drive home from work and migrate your funds if you're single sig under one of those without a passphrase, without Dice, or with a weak passphrase. But we're finding, and It's part of an ongoing investigation as to the current state of the ColdCard firmware, which would affect newer devices like the Q. We're finding that the problem still exists there too, but it's partially mitigated. So estimates right now are that current users of ColdCard devices are getting about 70 bits of security, whereas you're supposed to be getting 256 bits. during keygen. But that 70-bit number is even going down because we're finding that one of the fallback RNGs that is used to paper over the original defect is actually less random than we thought and is specified by the manufacturer. And, you know, they may be doing things like zeroing out certain parts of this ID and So it might actually be worse than we were thinking last night for current devices. So my headline for everybody at this point is if you're working off of a cold card device, Q, after 2021, you need to migrate your funds pretty expeditiously. If you did all the dice rolls, don't worry. you're probably in good shape. But even so, yeah, I think unfortunately people should be making moves to get off of the post-2021 devices.
Marty Bent [4:21] Yeah. I mean, we were trying to find some humor in light of this, but ColdCard. Hey, listen, I've been an advocate for ColdCard for many years. If you listen to the show, I've recommended it.
James O'Beirne [4:39] I have my queue right here.
Marty Bent [4:39] I moved my funds off. Last night, obviously, managing partner at 1031, we're invested in CoinKite, which produces the ColdCard. And this is very close to home for me personally, to many people I know that have felt very confident recommending this in the past. And it seems that the confidence was ill-gotten. We were, we were joking before. It's like the ColdCard souped up to secure enclaves, but you mess up one part of it, the random number generator. It's like you got a Ferrari on top of a lawnmower engine. Well, pretty devastating.
James O'Beirne [5:24] I'm in the same boat, man. I mean, I, I'm a single-sig passphrase guy on a ColdCard, you know, I think Mark II. Uh, my firmware is older and unaffected, but I love CoinKite. They make great products, but the unfortunate nature of security and hardware wallets is that you screw up one thing, you screw up the wrong one thing, and it's toast. And so that's the reason why people have been sort of paranoid in this department is because you just simply can't trust one manufacturer or one source for your entropy. When you're doing entropy construction, and this is what I do professionally for the last few years, is you have to be utterly paranoid when you're constructing a private key, and you can't just click a button and expect that it'll happen. So it's, yeah, it's really, It's really sad to see because I recommended ColdCard left and right to people who I thought were savvy enough to use them. And I'd say aside from getting yourself safe, my message to people would be think about who is a sort of more normal person than maybe you are listening to this podcast who you've recommended ColdCards to. maybe isn't following Bitcoin Twitter, give them a heads up if you got them set up with a ColdCard. I've got a few such people in my life that I've reached out to.
Marty Bent [7:09] Yeah. That's why I hit you up last night to record this. And I'm distracted right now because I'm about to send out a newsletter that just covers this as well. And I got to give one more prompt. To my client here to make something very clear here, but dive into the math. So you mentioned later versions, people are saying potentially 70 bits of entropy. You should have 256, MK2, MK3 after 2021, even less. I think it's like 30 bits.
James O'Beirne [7:44] Yeah, 20-something.
Marty Bent [7:46] And I mean, the nature of the attack, I mean, this is Obviously very much centered on CoinKite and ColdCard. However, AI comes into the mix. I mean, this is a new era of security vulnerabilities, and I mean, we've been talking about it for the better part of a couple years now on this show and others that these models, once they get sufficiently intelligent, will be able to uncover these. And it seems like that may be exactly what happened yesterday.
James O'Beirne [8:16] It's totally plausible, man. You know, me and a number of other researchers very quickly independently reproduced this just by giving the AI kind of a pointer as to, hey, you know, between this window of time, between these firmware versions, check for an RNG problem. And Kimi K3 chewed through it and found it readily. And yeah, look, if you're a sort of unscrupulous attacker and you're willing to just sit there and grind through, take any open-source Bitcoin software you can and just say, hey, file by file, go through, look at the entire history, find something that's plausibly an exploit. All that stuff's going to get unearthed. Somebody I was talking to yesterday put it this way. He said, security by obscurity is going to zero rapidly, and everything, the tide's washing out. So it's going to be really wild a few weeks and months and probably years.
Marty Bent [9:26] Yeah. I mean, outside of Bitcoin, Matt and I discussed it on RHR, but there was a water system in Minneapolis that was attacked. Looks like with some vibe-coded LLM attack. And what— how big of a setback do you think this is?
James O'Beirne [9:51] Well, you know me, man. I'm— I tend to be somewhat pessimistic in the short to midterm. And my real worry, aside from like the horrible tragedy of a bunch of good people losing their coins, that's obviously horrible. I'm a bit worried about the second-order effect of this being a hit against kind of the most reputable hardware wallet vendor among hardcore Bitcoiners, that kind of rippling out into a notion that, well, even the smart guys screwed up self-custody, and how can we expect that anybody will comfortably self-custody after this point?
Marty Bent [10:48] Yeah.
James O'Beirne [10:49] So I don't necessarily agree with that because again, if you kind of followed best practices that were recommended, You'd have avoided this pickle purely by obeying that principle that you can't trust a single manufacturer, or you have to bring your own entropy to the table somehow. But even so, I worry this event's going to get a lot of play, and maybe the general public is going to be like, oh yeah, that Bitcoin thing, that's impossible to keep safe by yourself. So just got to use a custodian.
Marty Bent [11:22] I mean, the irony of the whole situation is with all the eyes and compute focused on the Coldcard repository right now. By the end of the week, it may be the most secure system in the space. But again, the trust is very hard to build, very easy to break.
James O'Beirne [11:44] Yeah. And that's the problem. And in some ways, this is a sort of inexcusable error. if you are a company making the product that they make. And so I, you know, again, the CoinKite guys are friends of ours, certainly of yours and mine. And even so, it's like, I think it's—
Marty Bent [12:13] huh? What the fuck?
James O'Beirne [12:15] Yeah, it's going to be hard to trust anything that comes out of that brand anymore, you know? So it's, you know, I mean, the thing, like, it feels like every single hardware wallet manufacturer has made some kind of, like, fatal misstep again, because this domain is just very hard. You know, Ledger spilled, you know, all of their clients' information essentially back— what was that, like 2018?
Marty Bent [12:46] Twice.
James O'Beirne [12:46] Okay. Yeah, yeah. Probably multiple times. You know, BitBox had some pretty Pretty obvious physical defects that allowed key exfiltration. I don't know specifically if anything has befallen Trezor or not, but it's just— it's kind of the nature of the game that these things get hit with something. And even if they aren't obviously hit with something, the very fact that it's a security-critical Bitcoin device means that their whole supply chain's probably targeted. The companies themselves are targeted for intervention. So custody's tough, man. It's really tough. And I spent many years hoping we could make it easier with better scripting primitives and covenants and vaults. But I think given the community's more fractured than ever, I'm not sure we're going to get there and certainly not in the next year or two. But I don't know.
Marty Bent [13:55] I think this may light a fire under people's ass to figure out how to get that stuff through. I mean, a lot of the conversation, there's back and forth, people on both sides of the aisle, like, now's not the time to talk about this. And I think Alex B from— from Arc Labs. Arcade was making some good points. It's like, hey, don't worry about obscure covenants when we haven't even verified random number generation on some of these wallet providers.
James O'Beirne [14:24] There's a point there, but again, there's a sort of inescapable point, which is that even if you supposedly verify all the RNGs, you just can't— again, you can't trust one manufacturer. Even, look, I'll pick on, say, BitKey because that's being touted as a migration target. And I think the world of that team, and I know a lot of the guys who wrote that, they're super smart. But are you really auditing their whole software stack? BitKey requires on-device software that's closed source. I know a lot of it is open source, but some of their their backend services are closed source. So it's like, until you move some of that security into the chain itself, you're not going to be able to trust one provider. And until we solve that, it's like, okay, well, all right, so I go to 2 providers, I set up a multisig for myself. That's kind of a horrible user experience.
Marty Bent [15:35] Yeah.
James O'Beirne [15:37] Or a worse one for sure. So while, yeah, I mean, Alex's point is taken that there are fish to fry in the auditing department, I think the only categorical fix for a much better UX and multisig level security is going to be something at the covenant layer. So that's why it's important to kind of keep focus on that.
Marty Bent [16:04] I do think focus will be coming back to covenants pretty strongly here. That's my gut feeling. And as we've discussed throughout the years, I mean, the covenants vault conversation has been probably the most consistent continuous thread that we've had on this show, the conversations that you and I have had on the show over the last 2 or 3 years. And I think it is time to have that conversation. But I mean, bringing this back to LLMs and security, that's another frustrating thing is in your mind, as somebody who is a protocol engineer or somebody who's building custody systems for enterprises, what is the importance of basically fuzz testing your system with the latest models as soon as they're dropped?
James O'Beirne [16:55] Yeah, I'm doing it all the time now, both on the level of analysis as well as generating permanent test fixtures that are really solid, which is— that's a total blessing. It's easier than ever to say, hey, cross-test every cryptographic implementation I'm relying on against 2 or 3 other alternatives, make sure everything marries up. Oh, and then by the way, run a full audit of my entire system at both a conceptual level and an implementation level. That's incredible. And those are the same tools obviously that enable unearthing these kinds of attacks. And so it's the arms race. If you're not a diligent user of the latest AI models and techniques and you're building this stuff, then you're at a real disadvantage. And it really points you back in the direction of, man, this stuff has to be simple and rock solid.
Marty Bent [18:01] And it's incredibly frustrating. I mean, in parallel to all this happening, we have the The model wars here in the US and the government stepping in and cucking like Fable-5 and ChatGPT-5.6. And so that's, it's like if you're trying to audit these systems, you can't use the American frontier models because you get immediately nerfed and you're forced to figure out a way to get access to GPT-3, which I think many people are assuming that that is the model that was used to discover and then exploit this particular vulnerability with Cold Carb. And what are we doing in the US? The Operation Glass Wing, because I know many Bitcoin teams were like, hey, Anthropic, we have a pretty important system over here in Bitcoin. Can we get access to this to make sure that we're audited and finding any vulnerabilities or bugs that may exist. And I've heard that some teams in the space and maybe even core developers got access to it. But when it comes to something like a system like Bitcoin, we need the ability to audit this immediately now. Just thinking about, I think people really need to get through their mindset that the landscape of defensive technology has completely shifted and Like the way in which you secure your systems has changed, and it's being proactive and consistently proactive from here on out.
James O'Beirne [19:43] 100%. I was using Kimi exclusively last night to do the triage and investigation, and I was working with some colleagues, and the US-based models were just shutting, locking up, refusing to go further on certain lines of inquiry. I don't have a lot to say about the policy side. I haven't thought much about that. I'm sort of a freedom guy and I bless— I feel blessed that we have VPN technology. But yeah, the fact of the matter is if you're not kind of on the bleeding edge and you're doing security stuff, you're at a real disadvantage.
Marty Bent [20:26] Yeah. Bringing this back to Coldcard, walking through many scenarios, just thinking of the questions that many people who are just becoming aware of this may have in their mind. Let's walk through the scenarios going from MK3 past 2021 and obviously MK4, MK5, Q. What's the difference in terms of Vulnerability, exposure, and urgency to move coins. And then beyond that, you mentioned the dice. So to be clear, if you've set up a cold card and you added— you brought your own entropy by rolling dice, if you did it more than 100 times, you're very confident that you did, you should be good. You basically rolled your own entropy and are not affected by the RNG bug that exists. on the firmware or existed on the firmware yesterday. They have updated the firmware. So you can update that too for MK4, MK5, and Q if you want to get on something that's more secure than what existed yesterday. But if you do that, if you just update the firmware, that doesn't make you secure. You have to create a new private-public key pair and move the Bitcoin from your existing wallet to that new wallet that you set up there. Yeah.
James O'Beirne [21:49] The key point right there is it's not the firmware that's currently running on your device, it's what you generated your key with. So I could see that tripping some people up.
Marty Bent [22:01] Yeah.
James O'Beirne [22:02] But yeah, we initially thought the red zone was basically cold cards from '21 to '23. That footprint has expanded because we're hearing about MK4s that have been stolen from, and we have some indications of why that might be. But again, to reiterate, at this point, if you've generated a single sig with no passphrase, no dice roll on a CoinKite device post-'21, you got to get off pretty expeditiously.
Marty Bent [22:34] Yes. Multisig. I've talked to a number of people that are using cold cards in a multisig setup. Some are using 2 MK3s in a 2-out-of-3. What are the intricacies there? There's some nuance depending on if you've ever spent from that wallet, if you haven't. So if you have a 2-out-of-3 multisig using 2 MK3s or an MK3 and MK4, let's just go through those different scenarios. What And you've only sent Bitcoin to, you've never spent from, or you've both sent Bitcoin to and spent from? What is the exposure there? Yeah.
James O'Beirne [23:14] So multisig is where it gets pretty complicated. I think it'd help to maybe step back and just explain a little bit how multisig works or pay-to-witness script hash or Taproot. scripts in general in Bitcoin. When you spend from a multisig, you actually have to present the script that locked up the coins in the first place, which means you have to present the pubkey for each key involved in the multisig. And so what that can mean is if you're using a multisig with all cold cards and you've used, say, that address before, you've revealed all of your pub keys. And so an attacker could theoretically grind out all the private keys, you know, and construct a valid spend and be able to present a valid signature or a valid script. If you have a multisig quorum where you have like any device that isn't a ColdCard or a CoinKite product, and that has to be part of the critical spend threshold, then you're in good shape. Basically, your coins are protected by that segment of the multisig. So for example, if you have a 3-of-5 and you have— not that I hope anybody out there as a consumer has a 3-of-5, but a 3-of-5, But, you know, that would require signing with a device that isn't a CoinKite device affected by this. So you'd be, you'd be in good shape. If, for example, you're like an Unchained customer, let's say, and you're doing a 2-of-3, and let's say that you yourself used 2 affected cold cards at home, that's sort of an interesting situation because Depending on what Unchained does, their pubkey may or may not be on the chain. I don't know. You know, they'd be able to field this question. If their pubkey is available, then you are vulnerable. So I think the safe guidelines there are basically if in your multisig you have a situation where you could move the coins with only CoinKite products, I would move to get off of that. Because there are a lot of subtleties around, well, are the pub keys out there? Aren't they out there? Don't get too clever by half. And if you have a critical threshold of your multisig that can be provided by CoinKite products, I would just move. Don't think twice. So that's the long-short answer there.
Marty Bent [26:15] And what is the We assumed the time you had, like, say again, multisig 2-of-3, 2 MK3s, maybe the, the pub key is exposed, but compared to just a single sig MK3, no bring your own entropy, no passphrase. I've heard that if you have multisig, you probably have a couple of days the way these, these attacks are.
James O'Beirne [26:44] Yeah, it's, it's, that's, that's, that's my inclination to say, but With this stuff, you kind of have to assume that now that the vulnerability is out there, that the entire internet is going to be just like grinding on this. And so yeah, multisig is harder to scan for, for an attacker, but that's just a shallow throw more compute at it type problem.
Marty Bent [27:08] Yeah.
James O'Beirne [27:09] And I wouldn't, I wouldn't back up to that. And let me reiterate there when I say, you know, If you have a critical threshold of CoinKite devices able to sign for your multisig, that is assuming you didn't use dice, you don't have passphrase, and so on and so forth. That's just a kind of naive single sig. So if you've used 99 dice rolls on some of your CoinKite keys, I have verified by hand that that code path is safe. So you're okay. Don't worry about those. It's really just, yeah, if you just trusted the device to give you a good key.
Marty Bent [27:45] I'm trying to think of all the scenarios that we're having. The one question, have you heard of any white hats going after this? Because it's going to be messy. And there was some discussion. There was a Twitter Spaces last night I was listening in on. It was the moral conundrum a lot of people were discussing, like, should we rent GPU and just sweep the people who are exposed?
James O'Beirne [28:19] Yeah, that's an ethically gray area that I haven't sat down and put the right amount of consideration into. I have been contacted by people with prospective plans for that. I don't know if it's actively happening. There's obviously the problem of attribution. You know, if you do sweep those funds as a white hat, how do you then verify back? There's some indication that given the UID, if you bring the physical device. Yeah, exactly. If you can present, you know, but that's, you know, the mechanism for that hasn't been demonstrated to me conclusively. So So on the one hand, it's very difficult, and I personally wouldn't be rushing out to white hat this. But on the other hand, the real argument for that kind of thing is that there are a lot of users out there who are affected by this, who probably are not listening to podcasts and browsing Bitcoin Twitter, and those are the guys that are going to get ground down. over the next few weeks if they're not made aware of the situation. And so that's a real tricky one, man. Yeah, there's a big ethical dimension to that one, as well as probably like a legal dimension that, you know, you'd need to think through.
Marty Bent [29:50] Yeah. Yeah. I mean, That's like, does the, does the collapse in confidence of the CoinK cold cards lead to like a lack of confidence in other? And like, it goes back to the importance. Like, I've been a big believer of multi-vendor multisig. for this exact reason for, for many years. And, um, it's like there's a bunch of people wondering like, okay, cold cards— I don't have a cold card, but I'm looking at my Trezor, looking at my Ledger, like, are these okay? Like, should I worry? Like, um, I think no, you shouldn't be worried as of right now. Um, and maybe you won't ever have to be worried. There's the potential that the way they do their entropy and create their private-public key pairs is really top-notch and gives you enough. It gives you 256 bits of entropy that is secure and very hard and impossible to break, statistically improbable to break. And so if you're out there in that situation, do not panic. That's what I would say.
James O'Beirne [31:14] Yeah.
Marty Bent [31:16] Because that's one of the other big mistakes that many people will make, many people will lose coins by panicking and foot-gunning themselves in the process of trying to sweep coins or something like that.
James O'Beirne [31:27] Yeah. You always want to be doing test transactions of small amounts whenever you're sending anywhere. And that's crucial to keep in mind throughout all this if you're migrating your own stuff.
Marty Bent [31:43] Yeah. How do we know that exchanges have secure setups?
James O'Beirne [31:50] Well, I know that a few do firsthand, but yeah, I am not aware of any exchanges that, you know, would be vulnerable to this. And I would like to think that almost every exchange has put more thought into entropy generation than, hey, we're going to click a button on a consumer device and hope for the best. But this is a wake-up call for everybody, including enterprises that You really have to put tremendous amount of care and thought into this part of the process. And what I've always tried to emphasize to clients is you need at least one component of your entropy that you can physically reason about and that you understand in terms of how it's being incorporated. into the entropy. And so I think probably guys like us, consumers, are going to have to start to think about this. How do we take a very simple piece of code that we can reason about or have audited by somebody we trust and say, oh yeah, this is a part of the key now, for sure? Because yeah, I can see how this event would keep you up at night. You say, well, why couldn't this happen to Ledger? Why couldn't this happen to Trezor? What I will say is that CoinKite was a very lean— is a very lean company. And most other hardware wallet manufacturers, certainly Ledger and Trezor, have pretty big teams who are doing a lot of internal auditing. I mean, Ledger's— there's some phenomenal people there. This isn't an advertisement for Ledger or anything. I don't even use Ledger personally, but— There are some phenomenal people there who have done some very novel hardware attacks.
Marty Bent [34:13] The Donjon team. It's like, it's— yeah, joke last night is like they figured out a way to use $250,000 lasers to hack a gold card, but all they had to do was—
James O'Beirne [34:24] Yeah, yeah, exactly. So yeah, I mean, I still think, you know, a multi-manufacturer approach for guys like us is, is a, is a really solid approach. But, you know, as Nick Szabo said, it just echoes, you know, all the time, trusted third parties are security holes. And, uh, for something like this, you, you know, there's a certain level you can't delegate. to a packaged product. Not easy, man. It's really not easy, especially at the enterprise level, thinking about this stuff and designing it. It's a tough thing.
Marty Bent [35:15] Well, trying to find the silver lining in all this. I mean, it is horrible, disastrous, But something that Bitcoiners have said for a while, I think Bitcoin creates this honeypot to surface these vulnerabilities because the ability to send the bearer asset and actually have control of it with no clawbacks creates that incentive to find these vulnerabilities. And now with the AI tools, obviously that is accelerating. So I'd be interested to get your thoughts. Is there a silver lining where we're going to find these vulnerabilities And obviously there's already been collateral damage. There's likely going to be more collateral damage in the weeks to come. But on the other side, it's darkest before the dawn. On the other side, could you see Bitcoin actually being significantly more secure and the products around it being more secure a year from now because of the wake-up call that we just got in the last 24 hours?
James O'Beirne [36:21] Yeah, it's possible this could be a step along the antifragile path to essentially discovering the final form of individual-level Bitcoin security, because it's possible that we could get to some kind of deterministic endpoint where there's a system or a set of software or an arrangement where humans, machines have done all the analysis and have said, yeah, I mean, Yeah. If you do it this way with this binary on this platform, if it's simple enough, we could get to a point where ultimately this event has catalyzed a bunch of people to put the effort in and create something where you truly can't be hacked unless you get some physical component.
Marty Bent [37:19] Yeah.
James O'Beirne [37:20] And then even then, if something like this motivates a reinterest in vaults, well, even if you do get hacked, then you have a 6-hour window to claw into a trusted counterparty like an exchange. So yeah, I think conceivably this could be the kind of kick in the butt that the industry needed to start thinking about some of that stuff. There's a long timeline on that, and right now the community's pretty fractured, so I don't know.
Marty Bent [37:59] Yeah. I will say, I mean, in terms of protocol development, it certainly is fractured, but another silver lining, I mean, it was encouraging to see people come together publicly, behind the scenes. I mean, I think it was I mean, I was in DC at an event at PubKey and at the beginning of it, I was like, oh, what's going on? Then it became clear what's going on. I was just in the corner on my phone the whole night, like, all right, all hands on deck. And I think there was— it's weird too, because Bitcoin, there is no CEO to call. So it's people like Rob Hamilton, yourself, Portland HODL, and others hopping on Spaces to try to educate people about all this.
James O'Beirne [38:41] Yeah.
Marty Bent [38:43] I know behind the scenes many people reaching out, one node to many, like, hey, my guy. I wound up texting a friend being like, hey, are you aware of this? He's like, no, I've been heads down all day. And his brother is a coiner too and was on vacation. And he was able to go over to his house and he just sat on a bear single sig MK3 with no dice entropy or passphrase and was able to move it. And so that was like, okay. And I think there was much of that going on. And I think that's the spirit that we need to lean into heavily, particularly as this is unfolding, is obviously there's going to be a lot of justifiably angry people, very much justified. But I don't think this is the time to sling shit and throw people under the bus. It's like, okay, this is happening. While it's happening, let's just make sure we get as many people into— out of harm's way as possible.
James O'Beirne [39:49] Totally agree. And this thing is still ongoing, so it's still critical to give people heads up and just be racking your brain for anybody who may not be listening to podcasts, uh, you know, who has a cold card, um, because I, I think probably we're going to continue to see, uh, you know, funds flow around. Um, so, uh, yeah, I mean, it's, I, it's, it's hard to— this, the sentiment thing is difficult because like there is a kind of like, um, excitement and camaraderie that comes out of an event like this, but that we can only experience that because we didn't lose our life savings, you know? And there are people that happened to, and that's horrible. That's really horrible. It's not the worst thing, you know? If you're one of those people, God has a plan, and you need to keep that in mind. But yeah, it's it is good to see the the community kind of reorient in certain ways and come back to you know the the real. stuff of Bitcoin rather than chattering about $110,000 or whatever.
Marty Bent [41:26] Yeah. I think we can keep this short. Is there anything we missed we should be getting out there? I mean, it's probably— we should keep it short so we can get it out there to people as quickly as possible.
James O'Beirne [41:38] No, I mean, I think we hit the headlines. There's obviously tons of technical detail you could go into, but The investigation's still ongoing. So, um, you know, again, my headline is if you have a CoinKite device, uh, post-2021, uh, and you didn't use dice rolls, um, don't have a super strong passphrase that you know is cryptographically strong, you know, you need to expedite, um, getting your funds. My, my, you know, my recommend— recommendation for a lot of people would be find an exchange that you trust. And just, if you don't mind doxxing yourself, park your funds there while you figure out what the long-term is and just kind of get out of Dodge. Do a small test transaction. Don't panic, don't rush anything, but steady is smooth, smooth is fast. Yeah.
Marty Bent [42:41] Yeah. And just to clarify, if you're sitting there like, did I roll the dice enough? Is my passphrase strong enough? If you have 99 or more dice rolls and you did it correctly, you're confident in that, you should be fine. Passphrase, if you have 6 or more BIP-39 words as a passphrase, you should be good. Is that the sort of thresholds that are correct there in my mind?
James O'Beirne [43:06] Sorry, repeat. Password criteria?
Marty Bent [43:10] 6 BIP-39 words or more.
James O'Beirne [43:12] Maybe I wouldn't— I wouldn't hinge on that per se, because, you know, there are things like, are you mixing case for that? You know, each BIP-39 word is like drawn from a set of 2048. So 2,048 times 6 is in a big search space. That's why passphrases are tough because something you might think is pretty strong, given enough GPUs, is not.
Marty Bent [43:47] Okay.
James O'Beirne [43:49] So unless you're a specialist and you know your passphrase is crazy and strong, I would not rely on that. I'll be moving my small number of fractional Bitcoin around Even though I have, you know, I'm not affected by the firmware version and I have a strong passphrase, but even so, out of an abundance of caution, I'm just going to be moving.
Marty Bent [44:16] All right. Well, I hate that we had to meet here under these circumstances, but I really appreciate that you hopped on to walk through this. We'll get this out and warn people about all this.
James O'Beirne [44:28] Of course, man. Yeah. Good to see you.
Marty Bent [44:32] Good to see you too. Peace and love, freaks. Thank you. Thank you for listening to this episode of TFTC. If you've made it this far, I imagine you got some value out of the episode. If so, please share it far and wide with your friends and family. We're looking to get the word out there. Also, wherever you're listening, whether that's YouTube, Apple, Spotify, make sure you like and subscribe to the show. And if you can leave a rating, on the podcasting platforms. That goes a long way. Last but not least, if you want to get these episodes a day early and ad-free, make sure you download the Fountain podcasting app. You can go to fountain.fm to find that. $5 a month gets you every episode a day early, ad-free. Helps the show, gives you incredible value. So please consider subscribing via Fountain as well. Thank you for your time, and until next time. Okay.


